Ransomware Group intelligence
Wallstreet
ActiveTrack Wallstreet with 24 published victims and 1 known leak locations in a single intelligence view.
Overview
Wallstreet is tracked by Breach House as a ransomware group with 24 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 4h ago | 4dwiv37h7hhuhjpvtn72hme4ylcv3qoe65arfc6mbweal7als6ma7pyd.onion |
Top Activity Sectors (8)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Wallstreet, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: Wallstreet leverages PowerShell to execute malicious payloads and perform lateral movement across systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Wallstreet disables security tools by terminating antivirus processes and modifying system configurations to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: Wallstreet encrypts and encodes victim files using symmetric cryptography to ensure data remains inaccessible.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: Wallstreet performs file deletion to remove Volume Shadow Copies and backup artifacts to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1083 File and Directory Discovery Discovery
What they do: Wallstreet executes file and directory discovery to map critical system paths and user data before targeting.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1135 Network Share Discovery Discovery
What they do: Wallstreet uses network share discovery to locate victim file shares and identify high-value data for encryption.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1560.001 Archive via Utility Collection
What they do: Wallstreet archives victim data via utility commands prior to encryption to facilitate potential financial theft.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: Wallstreet encrypts victim files using custom ransomware binaries to achieve data encryption for impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: Wallstreet inhibits system recovery by disabling backup services and altering restore configurations.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: Wallstreet performs internal defacement by replacing victim content with ransom notes and contact information.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Victims (24)
Search, filter and paginate the victim timeline for Wallstreet. Showing 1–24 of 24.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | America’s Food Basket id32448 View details | United States | Retail / E-commerce | — | |
|
America's Food Basket operates within the United States retail and e-commerce sectors, providing grocery and online shopping solutions to consumers and businesses. As a prominent retail entity, it handles sensitive customer and transaction data, making it a potential target for cyber threats. This listing identifies America's Food Basket as a ransomware victim associated with the Wallstreet threat actor group. The entry reflects the entity's inclusion in a threat-intelligence index documenting cybersecurity incidents across sectors. Neutral documentation focuses on the verified association without speculating on breach details or attack mechanisms. |
|||||
| Ransomware | America’s Food Basket id32448 View details | United States | Retail / E-commerce | — | |
|
America’s Food Basket is a U.S. cooperative grocery-store network. Its site, afbasket.com, provides store locations, weekly ads, online shopping, delivery, recipes, and job listings. It operates under the America’s Food Basket and Ideal Food Basket names. |
|||||
| Ransomware | Ormond Beach Florida id32431 View details | United States | — | — | |
|
Ormond Beach Florida represents a geographic and commercial location within the United States, commonly associated with service-oriented sectors including hospitality, retail, and local business operations in the Ormond Beach region. Within this threat-intelligence catalog, it is documented specifically as a ransomware victim, linked to the Wallstreet threat actor group operating from or targeting entities in the US. This listing type indicates an association between the location or entity and a ransomware-related incident, without disclosing confirmed technical details, data scope, or financial impact. The entry serves to contextualize the entity within cybersecurity intelligence frameworks, highlighting its relevance to threat actor tracking and regional incident analysis. It was listed as a ransomware victim associated with Wallstreet. |
|||||
| Ransomware | Ormond Beach Florida id32431 View details | United States | — | — | |
|
Ormond Beach, Florida, is a scenic coastal city just north of Daytona Beach, known for its beaches, relaxed atmosphere, historic charm, and outdoor activities. |
|||||
| Ransomware | Total Education Solutions id32387 View details | United States | Education | — | |
|
Total Education Solutions operates within the United States education sector, providing technology and administrative solutions typically associated with educational institutions, including digital learning platforms, student management systems, and institutional support services. As a ransomware victim associated with the Wallstreet threat actor, it is cataloged in this threat-intelligence index to document cybersecurity incidents affecting education-focused entities. The listing reflects the entity's involvement in a ransomware event linked to Wallstreet, contextualized by its sector and geographic location without disclosing unconfirmed technical or operational details. This entry supports threat-intelligence research, sector risk assessment, and awareness of cyber threats targeting education infrastructure in the US. |
|||||
| Ransomware | Total Education Solutions id32387 View details | United States | Education | — | |
|
TES IDEA provides personalized educational, therapeutic, and developmental solutions that help students, families, and schools achieve better outcomes. |
|||||
| Ransomware | Cedar County Memorial Hospital id32337 View details | United States | Healthcare / Pharma | — | |
|
Cedar County Memorial Hospital operates within the United States healthcare and medicine sector, providing clinical services and hospital-based medical care to the community. As a healthcare institution, it handles sensitive patient data and critical operational systems, making it a recognized target category in cyber threat landscapes. This entity is documented in the threat-intelligence index under the classification of ransomware victim, associated with the Wallstreet threat actor. The listing reflects observed threat-intelligence linkage without confirming specific breach details, data scope, or operational impact. It serves as a reference point for monitoring healthcare sector security risks and attacker targeting patterns. |
|||||
| Ransomware | Cedar County Memorial Hospital id32337 View details | United States | Healthcare / Pharma | — | |
|
Cedar County Memorial Hospital is a community hospital providing emergency, inpatient, outpatient, diagnostic, surgical, and rehabilitation services. |
|||||
| Ransomware | Andover id32317 View details | United States | null | — | |
|
Andover is a company operating within the United States, with sector information not specified in available data. The entity is cataloged as a ransomware victim linked to the threat actor Wallstreet. This listing type indicates that Andover was identified within a threat-intelligence index as a target of ransomware activity associated with Wallstreet. The description remains neutral and avoids speculation regarding specific breach details, data exposure, or operational impact. It serves as a factual reference point for cybersecurity professionals monitoring threat actor activity and victim profiles across the US landscape. |
|||||
| Ransomware | Andover id32317 View details | United States | null | — | |
|
The Town of Andover, Massachusetts, is a municipal government organization that provides public services, administration, community programs, education resources, infrastructure support, and civic information to residents and businesses in Andover. |
|||||
| Ransomware | T.RAD North America id31519 View details | United States | Manufacturing / Engineering | — | |
|
T.RAD North America operates in the manufacturing and engineering sector in the United States, providing various offerings to its clients. As a company in this sector, it is involved in the design, development, and production of products. T.RAD North America was listed as a ransomware victim associated with Wallstreet |
|||||
| Ransomware | T.RAD North America id31519 View details | United States | Manufacturing / Engineering | — | |
|
T.RAD North America (tradna.com) is a Hopkinsville, Kentucky-based manufacturer focused on heat exchangers for thermal-management applications such as vehicle powertrains, HVAC/architectural systems, and emerging technologies like battery and fuel-cell cooling. |
|||||
| Ransomware | Black Hills Bentonite id31520 View details | United States | Manufacturing / Engineering | — | |
|
Black Hills Bentonite is a US-based company operating in the manufacturing and engineering sector, specifically producing bentonite products. The company is located in the Black Hills region and offers various bentonite-related products and services. Black Hills Bentonite was listed as a ransomware victim associated with Wallstreet. |
|||||
| Ransomware | Black Hills Bentonite id31520 View details | United States | Manufacturing / Engineering | — | |
|
Black Hills Bentonite LLC (bhbentonite.com) is a Wyoming-based producer of high-quality sodium bentonite, along with lignite-related products, supplying global industrial and commercial uses such as drilling fluids, environmental/civil engineering sealing, absorbents (including cat litter), and metal casting/foundry applications |
|||||
| Ransomware | Gold Standard Automotive id30256 View details | United States | Transportation / Travel / Logistics | — | |
|
Gold Standard Automotive is a company operating in the transportation sector in the US, providing services related to the automotive industry. The company is involved in various activities, including sales, maintenance, and logistics. Gold Standard Automotive was listed as a ransomware victim associated with Wallstreet |
|||||
| Ransomware | Gold Standard Automotive id30256 View details | United States | Transportation / Travel / Logistics | — | |
|
Gold Standard Automotive Network administers vehicle service contracts sold through dealerships, offering coverage for repairs after your factory warranty ends, with claim approvals handled through the company. |
|||||
| Ransomware | Baraga County Memorial Hospital id30257 View details | United States | Healthcare / Pharma | — | |
|
Baraga County Memorial Hospital is a healthcare facility located in the United States, providing medical services to its community. As a hospital, it offers various healthcare services, including emergency care, surgical services, and patient care. Baraga County Memorial Hospital was listed as a ransomware victim associated with Wallstreet |
|||||
| Ransomware | Baraga County Memorial Hospital id30257 View details | United States | Healthcare / Pharma | — | |
|
Baraga County Memorial Hospital is a critical access hospital serving Baraga County with emergency, surgery, imaging, rehab, and outpatient care. |
|||||
| Ransomware | Edgewood Police Department id30254 View details | United States | Public Sector | — | |
|
The Edgewood Police Department is a law enforcement agency serving the public sector in Edgewood, US, providing essential services to maintain public safety and order. As a public sector entity, it plays a critical role in the community. The Edgewood Police Department was listed as a ransomware victim associated with Wallstreet. |
|||||
| Ransomware | Edgewood Police Department id30254 View details | United States | Public Sector | — | |
|
The Edgewood Police Department is part of the Pierce County Sheriff’s Department, providing public safety and law enforcement services for the city. |
|||||
| Ransomware | Asisken id30255 View details | Ecuador | Other | — | |
|
Asisken operates in the other sector in Ecuador, providing various offerings to its customers. The company is involved in activities related to its sector, catering to the needs of its clients in the region. Asisken was listed as a ransomware victim associated with Wallstreet |
|||||
| Ransomware | Asisken id30255 View details | Ecuador | Other | — | |
|
Asisken (asisken.com) is a medical assistance/health insurance company offering prepaid medical coverage and member support services, with a hospital network in Ecuador (and Colombia). |
|||||
| Ransomware | Omax Autos id30040 View details | India | Manufacturing / Engineering | — | |
|
Omaxauto.com is a company based in India, operating in the manufacturing and engineering sector, providing various products and services. The company's offerings cater to the needs of its clients in the manufacturing and engineering industry. Omaxauto.com was listed as a ransomware victim associated with Wallstreet |
|||||
| Ransomware | Omax Autos id30040 View details | India | Manufacturing / Engineering | — | |
|
OMAX Autos Limited is a leading manufacturer of sheet metal components, specializing in the production of auto and non-auto components. |
|||||